nerdexam
CompTIA

SY0-701 · Question #928

A security analyst learns that an attack vector, which was used as a part of a recent incident, was a well-known IoT device exploit. The analyst needs to review logs to identify the time of initial ex

The correct answer is C. Firewall. The firewall is the choke point that records every inbound/outbound session to the IoT device; its timestamps on the first suspicious connection will most reliably show when the exploit traffic first hit the network. Reviewing those entries pinpoints the initial compromise time b

Submitted by lukas.cz· Mar 6, 2026Security Operations

Question

A security analyst learns that an attack vector, which was used as a part of a recent incident, was a well-known IoT device exploit. The analyst needs to review logs to identify the time of initial exploit. Which of the following logs should the analyst review first?

Options

  • AWireless access point
  • BSwitch
  • CFirewall
  • DNAC

How the community answered

(54 responses)
  • A
    2% (1)
  • B
    6% (3)
  • C
    81% (44)
  • D
    11% (6)

Explanation

The firewall is the choke point that records every inbound/outbound session to the IoT device; its timestamps on the first suspicious connection will most reliably show when the exploit traffic first hit the network. Reviewing those entries pinpoints the initial compromise time before diving into more granular device or segment logs.

Community Discussion

No community discussion yet for this question.

Full SY0-701 Practice